提交 6e501c47 编写于 作者: P Pauli

Fix spelling errors in documentation.

Also fix some clumsy wording.

[skip_ci]
Reviewed-by: NRichard Levitte <levitte@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/6545)
上级 445bc808
...@@ -43,9 +43,9 @@ L<SSL_CTX_set_session_cache_mode(3)>). ...@@ -43,9 +43,9 @@ L<SSL_CTX_set_session_cache_mode(3)>).
(SSL/TLS server only.) (SSL/TLS server only.)
SSL_CTX_sess_get_new_cb(), SSL_CTX_sess_get_remove_cb(), and SSL_CTX_sess_get_new_cb(), SSL_CTX_sess_get_remove_cb(), and
SSL_CTX_sess_get_get_cb() allow to retrieve the function pointers of the SSL_CTX_sess_get_get_cb() retrieve the function pointers set by the
provided callback functions. If a callback function has not been set, corresponding set callback functions. If a callback function has not been
the NULL pointer is returned. set, the NULL pointer is returned.
=head1 NOTES =head1 NOTES
......
...@@ -34,10 +34,10 @@ argument I<arg> is specified by the application when setting I<callback>. ...@@ -34,10 +34,10 @@ argument I<arg> is specified by the application when setting I<callback>.
I<callback> should return 1 to indicate verification success and 0 to I<callback> should return 1 to indicate verification success and 0 to
indicate verification failure. If SSL_VERIFY_PEER is set and I<callback> indicate verification failure. If SSL_VERIFY_PEER is set and I<callback>
returns 0, the handshake will fail. As the verification procedure may returns 0, the handshake will fail. As the verification procedure may
allow to continue the connection in case of failure (by always returning 1) allow the connection to continue in the case of failure (by always
the verification result must be set in any case using the B<error> returning 1) the verification result must be set in any case using the
member of I<x509_store_ctx> so that the calling application will be informed B<error> member of I<x509_store_ctx> so that the calling application
about the detailed result of the verification procedure! will be informed about the detailed result of the verification procedure!
Within I<x509_store_ctx>, I<callback> has access to the I<verify_callback> Within I<x509_store_ctx>, I<callback> has access to the I<verify_callback>
function set using L<SSL_CTX_set_verify(3)>. function set using L<SSL_CTX_set_verify(3)>.
......
...@@ -155,7 +155,7 @@ B<X509_CHECK_FLAG_NEVER_CHECK_SUBJECT> host flag, or because some DNS subject ...@@ -155,7 +155,7 @@ B<X509_CHECK_FLAG_NEVER_CHECK_SUBJECT> host flag, or because some DNS subject
alternative names are present in the certificate, DNS name constraints in alternative names are present in the certificate, DNS name constraints in
issuer certificates will not be applied to the subject DN. issuer certificates will not be applied to the subject DN.
As described in X509_check_host(3) the B<X509_CHECK_FLAG_NEVER_CHECK_SUBJECT> As described in X509_check_host(3) the B<X509_CHECK_FLAG_NEVER_CHECK_SUBJECT>
flag takes precendence over the B<X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT> flag. flag takes precedence over the B<X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT> flag.
X509_VERIFY_PARAM_get_hostflags() returns any host flags previously set via a X509_VERIFY_PARAM_get_hostflags() returns any host flags previously set via a
call to X509_VERIFY_PARAM_set_hostflags(). call to X509_VERIFY_PARAM_set_hostflags().
......
...@@ -222,7 +222,7 @@ This is in fact done automatically by L<RAND_DRBG_bytes(3)>. ...@@ -222,7 +222,7 @@ This is in fact done automatically by L<RAND_DRBG_bytes(3)>.
In most cases OpenSSL will automatically choose a suitable seed source In most cases OpenSSL will automatically choose a suitable seed source
for automatically seeding and reseeding its <master> DRBG. In some cases for automatically seeding and reseeding its <master> DRBG. In some cases
however, it will be necessary to explicitely specify a seed source during however, it will be necessary to explicitly specify a seed source during
configuration, using the --with-rand-seed option. For more information, configuration, using the --with-rand-seed option. For more information,
see the INSTALL instructions. There are also operating systems where no see the INSTALL instructions. There are also operating systems where no
seed source is available and automatic reseeding is disabled by default. seed source is available and automatic reseeding is disabled by default.
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册